Cloud Access Security Brokers (CASB)
A Cloud
Access Security Broker (CASB) is an on-premises or cloud-hosted security
enforcement point that sits between cloud service users and cloud service
providers. It consolidates security policy enforcement—such as authentication,
encryption, malware detection, and data loss prevention (DLP)—to protect
cloud-based applications, assets, and data across all devices.
The Four
Pillars of CASB
- Visibility: Uncovers Shadow IT by
identifying all sanctioned and unsanctioned cloud applications used across
the organization, tracking user activities, and evaluating vendor risk.
- Data Security: Enforces Data Loss Prevention
(DLP) policies to control how sensitive data is accessed, shared, or
downloaded. Employs encryption, tokenization, and digital rights
management (DRM) for data in transit and at rest.
- Threat Protection: Uses User and Entity Behavior
Analytics (UEBA) and threat intelligence to detect anomalous behavior,
compromised accounts, insider threats, and incoming malware.
- Compliance: Ensures cloud usage aligns with
regulatory standards (e.g., GDPR, HIPAA, PCI DSS) and corporate governance
mandates by auditing cloud configurations and access logs.
CASB
Deployment Architecture
- API-Based Mode: Connects directly to cloud
providers via APIs. Provides full inspection of data at rest, audit logs,
and policy control without routing user traffic.
- Forward Proxy: Routes corporate network
traffic to cloud services via an agent or proxy. Enforces policies inline
before traffic leaves the boundary.
- Reverse Proxy: Routes inbound user traffic to
sanctioned corporate cloud applications. Enforces authentication and
inline inspection on managed and unmanaged devices.
Primary
Enterprise Use Cases
- Shadow IT Management: Discovering unsanctioned SaaS
applications accessed by employees on the corporate network.
- Granular Access Control: Restricting specific user
actions (e.g., allow "View", block "Download") based
on user context and device health.
- Cloud DLP Enforcement: Automatically scanning files
uploaded to cloud storage (Google Drive, OneDrive, AWS S3) for sensitive
tokens or compliance violations.
- User & Entity Behavior
Analytics (UEBA): Detecting abnormal access patterns, such as impossible travel
logins or mass file deletions.